Contribution model
One manifest describes one package and can combine several contributions. The package remains one installation, grant, update, and provenance boundary while each contribution declares its own behavior and permissions.
| Author goal | Contribution family | Current reference and boundary |
|---|---|---|
| Connect a model | LLM provider | All four signed Ollama packages passed offline and local Gemma tests using a source-built protocol-2 runner. The live checks completed tool calls and continuation in all four languages. Stable 0.7.8 ships protocol 1, so these guests need a newer app release. |
| Add an agent capability | Tool, action, skill, or MCP contribution | Tools, actions, and data sources use host-stamped context and declared grants. The issue lookup reference uses one approved Streamable HTTP endpoint. |
| Add a workflow step | Workflow Text Stats tool | All four signed packages passed installed-host tests with a source-built protocol-2 runner, including configuration, grant-revocation, and package-change checks. Stable 0.7.8 ships protocol 1; the workflow example needs a newer app release. |
| React to product activity | Event subscription or publisher | Mail Watch has a persisted installed-host fixture journey for TypeScript; live Graph account acceptance remains open. |
| Run integration work | Background service | The host owns schedules, leases, retries, health, and stop. A package declaration alone does not activate a service. |
| Read or transform conversation data | Message observer or middleware | Conversation Insights and Prompt Redactor have four-language references; message grants and installed request-path acceptance remain open. |
| Add interface | Accessible Theme sandboxed-web sample | Windows isolation checks passed 7/7 in a source-built app. Signed package and account-grant checks are still underway. Linux custom panels are unavailable; mobile is unsupported. |
| Open an installed extension panel in Glixo Code | code.main-panel host surface |
Host lifecycle tests passed 14 cases. Windows isolation checks passed 7/7 in a source-built app; signed install and grant checks are still underway. Linux custom panels are unavailable; mobile is unsupported. |
| Build reusable controls | @glixo/extension-ui authoring helper |
Preview source for extension authors; the helper itself is not an installable extension or theme. |
| Change Glixo appearance | Theme contribution | Planned. Glixo Code has no installed-theme selector or apply flow; the sandboxed UI sample does not change host appearance. |
| Access workspace data | Data source or storage contribution | Workspace Health, Document Index, and Workspace Storage use bounded host operations and invocation-scoped authority. |
These examples are teaching references, not marketplace entries. Read Tutorials for per-family evidence and Reference for exact source pins and remaining gates.
Manifest versus distribution envelope
glixo.extension.json is the guest contribution manifest. Its schemaVersion is 2. It declares package identity, contributions, requested capabilities and permissions, component entries, and configuration. This schema version is not a package type and does not itself grant authority. The generic contribution WIT world is 1.0.0; the provider HTTP/WIT ABI is 3.0.0. They are independent of the manifest and package-envelope versions.
The existing glixo.module.json distribution metadata envelope is version 1. Publisher signature canonicalization is version 2. Both are outside the guest manifest and versioned independently from the provider HTTP/WIT ABI. The envelope can describe a package carrying a v2 glixo.extension.json; do not put envelope-only fields into the guest schema or treat a valid manifest as proof that the catalog accepted or installed the package.
The exact v2 schema and outer-envelope reference are in Manifest and distribution reference. The generated copy is pinned to a source commit and cannot be edited in the portal.
Contribution closure
A declaration is only the first link. A contribution is available when installation, account or app activation, registration, invocation context, sidecar, guest export, broker operations, and the user-visible result all connect. The current implementation slices use these labels:
- Preview source: implementation excerpts are available at the source identity shown by the page.
- Host gate open: a production-consumable consumer-to-guest journey or supported distribution is not yet qualified.
- Available: the documented package has passed its installed-host acceptance for the named contribution and platform.
Do not infer support from a schema entry, generated model, unit fixture, or compiler demo.